The rulebook is being tidied up, not torn up
In an earlier article we walked through four other EU rules that might apply to your business as though each were a separate box to tick. The EU has reached much the same conclusion — that these rules had started to overlap, duplicate one another and occasionally pull in different directions. The “Digital Omnibus”, published by the European Commission on 19 November 2025, is its attempt to tidy that up.
This matters to you not because the underlying obligations are disappearing, but because deadlines, paperwork and thresholds you may already have planned around are moving — and because one half of the package is now law while the other half is still being argued over.
One package, two very different files
This is the single most important thing to understand, and the thing most coverage gets wrong. The Digital Omnibus is two separate legislative files, and they are at completely different stages:
- The Digital Omnibus on AI — adopted and in force. This is Regulation (EU) 2026/1744: approved by the Council on 29 June 2026, signed on 8 July 2026, published in the Official Journal on 24 July 2026 and in force since 27 July 2026. It amends the AI Act.
- The Digital Omnibus (the “data” half) — still a proposal. Formally it would amend the GDPR, the ePrivacy Directive, NIS2, the Data Act, the Critical Entities Resilience Directive, the Single Digital Gateway Regulation and the data protection rules for EU institutions — and repeal four instruments outright, including the Data Governance Act. It remains in negotiation between the European Parliament and the Council. Nothing in it is law.
If someone tells you the GDPR has been relaxed, or tries to sell you a product on the basis that consent rules have already changed, that claim is ahead of the law.
What the AI half actually did
Regulation (EU) 2026/1744 moved the compliance dates for high-risk AI systems: to 2 December 2027 for the standalone Annex III systems, and 2 August 2028 for AI embedded in products already covered by EU product-safety law. It also added new prohibited practices, which apply from 2 December 2026.
What it did not move is just as important: the Article 50 transparency obligations took effect on 2 August 2026 as originally planned. We cover the detail in EU AI Act: What Actually Changed on 2 August 2026.
What the data half would change — if it passes
The proposal is wide-ranging. The ideas attracting the most attention include single-click accept and reject for cookies and online tracking, browser-level preference signals so people can express a choice once rather than site by site, a moratorium on re-asking after a refusal, and a single entry point for incident reporting. That last one is worth a moment: the proposal would route the closely connected reporting duties under NIS2, the GDPR, DORA, eIDAS and the CER Directive through one door. DORA itself is not being amended — but if you report incidents under it, the way you file them could still change.
There are also more fundamental proposals: changes to the definition of personal data, wider use of legitimate interest and special-category exemptions for AI development, limits on data subject access requests, and adjustments to transparency, automated decision-making, breach notification and data protection impact assessments.
The Commission’s stated aim across the whole simplification drive is to cut administrative burden by at least 25% for businesses generally and at least 35% for small and medium enterprises by 2029.
It is not a smooth ride, and that tells you something
Two signals are worth knowing about, because they explain why we are not advising anyone to plan around this yet.
First, the EU’s own data protection authorities pushed back hard. In Joint Opinion 2/2026, adopted on 10 February 2026, the European Data Protection Board and the European Data Protection Supervisor supported the simplification aims but warned that parts of the proposal risk narrowing the scope of data protection and creating legal uncertainty. They firmly opposed revising the definition of personal data — a change that would ripple through everything, because it decides what the GDPR applies to in the first place. They did welcome the measures on scientific research, breaches and DPIAs.
Second, the Council’s own working text has reportedly dropped several of the core cookie-consent provisions. The headline feature many businesses are looking forward to may not survive the negotiation intact.
What this means practically, right now
- Do not treat this as deregulation. Core obligations under the GDPR, the AI Act and NIS2 are not going away. The Omnibus changes how they are administered and, for AI, when some deadlines land.
- Do not assume your deadline moved. The confirmed AI Act delay applies to high-risk obligations specifically. Transparency rules were untouched and are live now.
- Change nothing about your cookie banner yet. The consent reforms are proposals, some of them contested. Your current consent obligations stand.
- Build on principles, not dates. A lawful basis, data minimisation, security by design and accountability are not what is being simplified away. Compliance built on them survives whatever the final text says.
We will update this article once the data half reaches political agreement, the way the AI half already has.
Wondering which parts of this actually reach your business, and which are just noise? Let’s Talk GDPR.
Related reading
- EU AI Act: What Actually Changed on 2 August 2026 — and What’s Still Coming
- Beyond GDPR: Four Other EU Rules That Might Apply to Your Business
- What is Consent Under GDPR?
- What is a Lawful Basis Under GDPR?
- GDPR Glossary
References
- European Commission, Digital Omnibus package (19 November 2025) — proposals to simplify the EU digital legislative framework, comprising the Digital Omnibus and the Digital Omnibus on AI.
- Proposal for a Regulation, COM/2025/837 final (Digital Omnibus) — amending Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725 and (EU) 2023/2854 and Directives 2002/58/EC, (EU) 2022/2555 and (EU) 2022/2557, and repealing Regulations (EU) 2018/1807, (EU) 2019/1150 and (EU) 2022/868 and Directive (EU) 2019/1024. The explanatory text also provides for a single entry point covering incident reporting under NIS2, the GDPR, DORA, eIDAS and the CER Directive.
- Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI) — amending Regulation (EU) 2024/1689 (AI Act); published in the Official Journal 24 July 2026, in force 27 July 2026.
- Regulation (EU) 2024/1689 (AI Act) — Article 50 (transparency obligations, applicable from 2 August 2026) and Chapter III (high-risk systems).
- EDPB-EDPS Joint Opinion 2/2026 (adopted 10 February 2026) — on the proposal for a Regulation as regards the simplification of the digital legislative framework (Digital Omnibus).
- Regulation (EU) 2016/679 (GDPR) — the instrument the data half of the Omnibus proposes to amend.
- European Parliament Legislative Train Schedule — Digital Omnibus Regulation proposal — current status of the file in the legislative process.